Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.18% | — | Openpanel Openadmin | 14/3/2025 | 17/6/2026 | Cross Site Request Forgery vulnerability in Open Panel OpenAdmin v.0.3.4 allows a remote attacker to escalate privileges via the Change Root Password function | |
| Aplazada | Media (4.3) | 0.17% | — | Ravinder Khurana WP Hide Admin BARAI | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ravinder Khurana WP Hide Admin Bar wp-hide-admin-bar allows Cross Site Request Forgery.This issue affects WP Hide Admin Bar: from n/a through <= 2.0. | |
| Aplazada | Media (4.7) | 0.33% | — | Akshar Soft Solutions AS English AdminAI | 11/3/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Akshar Soft Solutions AS English Admin as-english-admin allows Phishing.This issue affects AS English Admin: from n/a through <= 1.0.0. | |
| Analizada | Media (5.3) | 0.37% | — | Wpase Admin AND Site Enhancements | 4/3/2025 | 17/6/2026 | The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate their value to bypass the login limit feature in the Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10. | |
| Aplazada | Media (6.9) | 0.25% | 💥 PoC | Famatech Advanced Port ScannerAIRadmin Advanced IP ScannerAI | 3/3/2025 | 17/6/2026 | Vulnerability of unauthorized exposure of confidential information affecting Advanced IP Scanner and Advanced Port Scanner. It occurs when these applications initiate a network scan, inadvertently sending the NTLM hash of the user performing the scan. This vulnerability can be exploited by intercepting network traffic… | |
| Aplazada | Crítica (9.8) | 2.1% | 💥 Exploit | VUE Vben AdminAI | 27/2/2025 | 17/6/2026 | Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials. | |
| Aplazada | Media (4.3) | 0.17% | — | Required Admin Menu ManagerAI | 26/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Required Admin Menu Manager allows Cross Site Request Forgery.This issue affects Admin Menu Manager: from n/a through 1.0.3. | |
| Modificada | Media (6.1) | 0.31% | — | Dynamiapps Frontend Admin | 25/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shabti Kaplan Frontend Admin by DynamiApps acf-frontend-form-element allows Reflected XSS.This issue affects Frontend Admin by DynamiApps: from n/a through <= 3.25.17. | |
| Analizada | Media (5.4) | 0.31% | — | Covertnine C9 Admin Dashboard | 21/2/2025 | 17/6/2026 | The C9 Admin Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | |
| Aplazada | Alta (7.1) | 0.25% | — | Johannes VAN Poelgeest Admin Options PagesAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Johannes van Poelgeest Admin Options Pages admin-options-pages allows Reflected XSS.This issue affects Admin Options Pages: from n/a through <= 0.9.7. | |
| Aplazada | Alta (8.7) | 0.56% | — | Siemens Simatic PCS NEOAISiemens Simocode ESAISiemens Sirius Safety ESAISiemens Sirius Soft Starter ESAI+1 | 11/2/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1), SIMOCODE ES V19 (All versions < V19 Update 1), SIRIUS Safety ES V19 (TIA Portal) (All versions < V19 Update 1), SIRIUS Soft Starter ES… | |
| Analizada | Baja (2.3) | 0.72% | — | GNU BinutilsNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility | 11/2/2025 | 17/6/2026 | A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The… | |
| Analizada | Media (6.3) | 0.80% | — | GNU BinutilsNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility | 11/2/2025 | 17/6/2026 | A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The… | |
| Analizada | Media (4.8) | 0.36% | — | Beian.miit Cool-admin-java | 10/2/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Parameter List module of cool-admin-java v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the internet pictures field. | |
| Analizada | Alta (7.2) | 0.85% | — | Beian.miit Cool-admin-java | 10/2/2025 | 17/6/2026 | An arbitrary file upload vulnerability in the component /comm/upload of cool-admin-java v1.0 allows attackers to execute arbitrary code via uploading a crafted file. | |
| Modificada | Media (6.9) | 0.52% | — | Pimcore Admin Classic Bundle | 7/2/2025 | 17/6/2026 | pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.7.4 and all users… | |
| Aplazada | Alta (7.1) | 0.14% | — | Victor Barkalov Custom Links ON Admin Dashboard ToolbarAI | 7/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Victor Barkalov Custom Links On Admin Dashboard Toolbar customize-wpadmin allows Stored XSS.This issue affects Custom Links On Admin Dashboard Toolbar: from n/a through <= 3.3. | |
| Aplazada | Alta (7.1) | 0.15% | — | Venugopal Show Notice OR Message ON Admin AreaAI | 7/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Show notice or message on admin area show-notice-or-message-on-admin-area allows Stored XSS.This issue affects Show notice or message on admin area: from n/a through <= 2.0. | |
| Aplazada | Alta (7.1) | 0.15% | — | Thunderbax WP Admin Custom PageAI | 7/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in thunderbax WP Admin Custom Page wp-admin-custom-page allows Stored XSS.This issue affects WP Admin Custom Page: from n/a through <= 1.5.0. | |
| Analizada | Baja (3.4) | 0.69% | — | Haxx CurlNetapp H700s FirmwareNetapp H615c FirmwareNetapp H610s Firmware+12 | 5/2/2025 | 17/6/2026 | When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance. | |
| Aplazada | Alta (7.5) | 0.40% | — | Bowo Admin AND Site EnhancementsAI | 4/2/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Bowo Admin and Site Enhancements (ASE) admin-site-enhancements allows Privilege Escalation.This issue affects Admin and Site Enhancements (ASE): from n/a through <= 7.6.2.1. | |
| Modificada | Crítica (9.8) | 0.56% | — | Eladmin | 3/2/2025 | 17/6/2026 | eladmin <=2.7 is vulnerable to CSV Injection in the exception log download module. | |
| Aplazada | Alta (7.5) | 0.44% | — | Notfound Admin AND Site Enhancements PROAI | 3/2/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in NotFound Admin and Site Enhancements (ASE) Pro allows Privilege Escalation. This issue affects Admin and Site Enhancements (ASE) Pro: from n/a through 7.6.2.1. | |
| Aplazada | Media (4.3) | 0.24% | — | Admin AND Site Enhancements ASE PROAI | 27/1/2025 | 17/6/2026 | Missing Authorization vulnerability in NotFound Admin and Site Enhancements (ASE) Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Admin and Site Enhancements (ASE) Pro: from n/a through 7.6.1.1. | |
| Analizada | Media (5.1) | 0.38% | — | Dcatadmin Dcat Admin | 24/1/2025 | 17/6/2026 | A vulnerability was found in Dcat-Admin 2.2.1-beta. It has been rated as problematic. This issue affects some unknown processing of the file /admin/auth/roles of the component Roles Page. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public… |